<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-id not updating mappings fast enough in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64156#M38525</link>
    <description>&lt;P&gt;We have 2 user-agents deployed that read the AD logs and the PA7050's connect to the user-agents. The agents are running 6.0.7-10 and the PA7050's running 6.1.4.&lt;/P&gt;&lt;P&gt;We are having a problem where mulitple machines across various networks are using a "generic" login account. We have policies in place on the PA7050's that are enforced on these macihines through user-id. This works fine until an admin logs into one of these machines or runs an application as an admin on the machine. This over-writes the user-id mapping by design. The issue however comes when the admin logs out and then logs back in as the generic account, the user-id mappings are not being updated fast enough or at all it seems, which then leaves that machine to bypass the enforcment policies.&lt;/P&gt;&lt;P&gt;Has anyone else run into this issue?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;**I have thought of using the ignore-list for the admin login's, however this would be a few 100 names and could change monthly which is not really scable to daily operations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2015 20:39:20 GMT</pubDate>
    <dc:creator>Gun-Slinger</dc:creator>
    <dc:date>2015-09-03T20:39:20Z</dc:date>
    <item>
      <title>User-id not updating mappings fast enough</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64156#M38525</link>
      <description>&lt;P&gt;We have 2 user-agents deployed that read the AD logs and the PA7050's connect to the user-agents. The agents are running 6.0.7-10 and the PA7050's running 6.1.4.&lt;/P&gt;&lt;P&gt;We are having a problem where mulitple machines across various networks are using a "generic" login account. We have policies in place on the PA7050's that are enforced on these macihines through user-id. This works fine until an admin logs into one of these machines or runs an application as an admin on the machine. This over-writes the user-id mapping by design. The issue however comes when the admin logs out and then logs back in as the generic account, the user-id mappings are not being updated fast enough or at all it seems, which then leaves that machine to bypass the enforcment policies.&lt;/P&gt;&lt;P&gt;Has anyone else run into this issue?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;**I have thought of using the ignore-list for the admin login's, however this would be a few 100 names and could change monthly which is not really scable to daily operations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 20:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64156#M38525</guid>
      <dc:creator>Gun-Slinger</dc:creator>
      <dc:date>2015-09-03T20:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: User-id not updating mappings fast enough</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64160#M38526</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not sure if its acceptable in your environemnt, but perhaps wmi probing could be used? Just be careful of where you have it enabled:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User-id Best practices:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Best-Practices-for-Securing-User-ID-Deployments/ta-p/61606" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Best-Practices-for-Securing-User-ID-Deployments/ta-p/61606&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security impact of wmi probing&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Customer-advisory-Security-Impact-of-User-ID-Misconfiguration/ta-p/59968" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Customer-advisory-Security-Impact-of-User-ID-Misconfiguration/ta-p/59968&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 23:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64160#M38526</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-03T23:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-id not updating mappings fast enough</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64162#M38528</link>
      <description>&lt;P&gt;Or maybe Captive portal, although I must admit I think it would be for all users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/user-id/map-ip-addresses-to-user-names-using-captive-portal.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/user-id/map-ip-addresses-to-user-names-using-captive-portal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 23:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64162#M38528</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-03T23:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-id not updating mappings fast enough</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64195#M38535</link>
      <description>&lt;P&gt;Maybe I'm mistaken, but in the user-agent config,the "Security Log Monitor Fequency (sec.)" setting should take care of this for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The login / run-as from the admin, log-off and subsequent login as a normal user should be recorded within this setting. &amp;nbsp;In our enviornment this is set as 3 seconds. &amp;nbsp;So unless I'm not understanding this correctly our enviornment would have this updated in 3 seconds or so, and would also take care of your issue as well.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 14:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64195#M38535</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-04T14:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: User-id not updating mappings fast enough</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64213#M38542</link>
      <description>&lt;P&gt;Global Protect in internal mode or wifi/nac logs are the only options. Anything else is just noise.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 20:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-updating-mappings-fast-enough/m-p/64213#M38542</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-09-04T20:03:31Z</dc:date>
    </item>
  </channel>
</rss>

